Bug#775227: patch: directory traversal via symlinks

2015-01-18 Thread Salvatore Bonaccorso
Control: retitle -1 patch: CVE-2015-1196: directory traversal via symlinks Hi, This has been assigned CVE-2015-1196 by MITRE. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#775227: patch: directory traversal via symlinks

2015-01-12 Thread Jakub Wilk
Package: patch Version: 2.7.1-6 Tags: security patch now support git-style patches, which allows creating symlinks. This feature can be abused for directory traversal. As a proof of concept, applying the attached patch creates a file in /tmp: $ ls /tmp/moo /bin/ls: cannot access /tmp/moo: No